Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 64 of 89
CVE-2015-1123P4MEDIUMCVSS 6.8v8.3
CVE-2015-1123 [MEDIUM] CVE-2015-1123: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1123
Component: CVE-2015-1076
apple
CVE-2015-7005P4MEDIUMCVSS 6.8v9.1
CVE-2015-7005 [MEDIUM] CVE-2015-7005: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7005
Component: CVE-2015-6982
apple
CVE-2015-6981P4MEDIUMCVSS 6.8v9.1
CVE-2015-6981 [MEDIUM] CVE-2015-6981: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6981
Component: CVE-2015-6981
apple
CVE-2015-7499P4MEDIUMCVSS 5.0v9.3
CVE-2015-7499 [MEDIUM] CVE-2015-7499: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-7499
Component: CVE-2015-7499
apple
CVE-2021-30788P4HIGHCVSS 7.1≥ unspecified, < 14.72021-09-08
CVE-2021-30788 [HIGH] CVE-2021-30788: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5,
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2015-1819P4MEDIUMCVSS 5.0v9.3
CVE-2015-1819 [MEDIUM] CVE-2015-1819: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-1819
Component: CVE-2015-1819
apple
CVE-2017-7830P4MEDIUMCVSS 6.5v11.2.52018-01-23
CVE-2017-7830 [MEDIUM] CVE-2017-7830: iOS 11.2.5
Apple Security Update: About the security content of iOS 11.2.5
Product: iOS
Version: 11.2.5
CVE: CVE-2017-7830
Component: WebKit Page Loading
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2020-9842P4HIGHCVSS 7.1≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9842 [HIGH] CVE-2020-9842: An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 an
An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application could interact with system processes to access private information and perform privileged actions.
nvd
CVE-2020-9808P4HIGHCVSS 7.1≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9808 [HIGH] CWE-787 CVE-2020-9808: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2016-1858P4MEDIUMCVSS 6.5v9.3.2
CVE-2016-1858 [MEDIUM] CVE-2016-1858: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1858
Component: CVE-ID
apple
CVE-2016-4587P4MEDIUMCVSS 6.5v9.3.32016-07-18
CVE-2016-4587 [MEDIUM] CVE-2016-4587: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4587
Component: WebKit
Impact: Visiting a maliciously crafted website may result in the disclosure of process memory
Description: A memory initialization issue was addressed through improved memory handling.
apple
CVE-2017-7038P4MEDIUMCVSS 6.1v10.3.32017-07-19
CVE-2017-7038 [MEDIUM] CVE-2017-7038: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7038
Component: WebKit
Impact: Processing maliciously crafted web content with DOMParser may lead to cross site scripting
Description: A logic issue existed in the handling of DOMParser. This issue was addressed with improved state management.
apple
CVE-2018-4428P4HIGHCVSS 7.1≥ unspecified, < 12.12020-10-27
CVE-2018-4428 [HIGH] CVE-2018-4428: A lock screen issue allowed access to the share function on a locked device. This issue was addresse
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 12.1.1. A local attacker may be able to share items from the lock screen.
nvdapple
CVE-2014-4494P4MEDIUMCVSS 6.8v8.1.3
CVE-2014-4494 [MEDIUM] CVE-2014-4494: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4494
Component: CVE-ID
apple
CVE-2018-4409P4MEDIUMCVSS 6.5v12.12018-10-30
CVE-2018-4409 [MEDIUM] CVE-2018-4409: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4409
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A resource exhaustion issue was addressed with improved input validation.
apple
CVE-2018-4271P4MEDIUMCVSS 6.5v11.4.12018-07-09
CVE-2018-4271 [MEDIUM] CVE-2018-4271: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4271
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2022-22658P4MEDIUMCVSS 6.5≥ unspecified, < 16.02022-11-01
CVE-2022-22658 [MEDIUM] CWE-20 CVE-2022-22658: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 16.0.3. Processing a maliciously crafted email message may lead to a denial-of-service.
nvdapple
CVE-2017-2475P4MEDIUMCVSS 6.1v10.32017-03-27
CVE-2017-2475 [MEDIUM] CVE-2017-2475: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2475
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in frame handling. This issue was addressed through improved state management.
apple
CVE-2020-3841P4MEDIUMCVSS 6.5≥ unspecified, < iOS 13.3.1 and iPadOS 13.3.12020-02-27
CVE-2020-3841 [MEDIUM] CWE-319 CVE-2020-3841: The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
nvd
CVE-2020-3867P4MEDIUMCVSS 6.1≥ unspecified, < iOS 13.3.1 and iPadOS 13.3.12020-02-27
CVE-2020-3867 [MEDIUM] CWE-79 CVE-2020-3867: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iP
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd